SUSE-CU-2026:7312-1: Security update of suse/sl-micro/6.0/toolbox

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 24 10:34:05 UTC 2026


SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7312-1
Container Tags        : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.137 , suse/sl-micro/6.0/toolbox:latest
Container Release     : 9.137
Severity              : important
Type                  : security
References            : 1268290 1269790 CVE-2026-11979 CVE-2026-54411 
-----------------------------------------------------------------

The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 806
Released:    Wed Jul 22 10:36:01 2026
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1269790,CVE-2026-11979
This update for libxml2 fixes the following issue

- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).

-----------------------------------------------------------------
Advisory ID: 805
Released:    Wed Jul 22 10:38:14 2026
Summary:     Security update for pam
Type:        security
Severity:    moderate
References:  1268290,CVE-2026-54411
This update for pam fixes the following issue

- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).


The following package changes have been done:

- SL-Micro-release-6.0-25.112 updated
- libxml2-2-2.11.6-13.1 updated
- pam-1.6.0-6.1 updated
- skelcd-EULA-SL-Micro-2024.01.19-8.111 updated


More information about the sle-container-updates mailing list